Impact
The Ads Pro WordPress plugin contains a stored cross‑site scripting flaw due to improper neutralization of user input during web page generation. The vulnerability allows attacker traffic that includes malicious HTML or JavaScript to be persisted and later executed in the browsers of site visitors, enabling data theft, session hijacking or defacement of the site. This weakness is a classic input validation failure (CWE‑79) that manifests as stored XSS.
Affected Systems
All installations of the scripteo Ads Pro plugin with versions 5.0 or older are affected. The vulnerability does not impact other WordPress plugins or core components.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate impact. The EPSS score of less than 1 % suggests that the likelihood of exploitation is currently very low, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is the plugin’s content or ad creation interface, where an authorized or compromised author/administrator can submit and store malicious payloads that are rendered to all site visitors.
OpenCVE Enrichment
EUVD